To the Hacker News crowd, I think that anybody that read the timeattack's comment has thought: a server application that output files given a filepath? Maybe we can forge some absolute path? And then, 5 minutes later, on Github, you confirm your hypothesis by reading 62 lines of Go.
Nevertheless, I am respectful of responsible security disclosure. Maybe timeattack will prefer to use an entirely private channel to communicate with the server owner the next time?
In the end, the info was already out, the author fixed it real quick and I hoped he has cleaned its server by now ;)
I like the idea of crowdsourced effort to build useful datasets. Nevertheless, with growing popularity, I can imagine a whole lot of potential abuse of the voting API, e.g: blacklisting competitors channels.
By the way, the repo author has done a lot of work to develop a whole USB attack platform based on Raspberry Pi 0, which really deserve some interests:
Nevertheless, I am respectful of responsible security disclosure. Maybe timeattack will prefer to use an entirely private channel to communicate with the server owner the next time?
In the end, the info was already out, the author fixed it real quick and I hoped he has cleaned its server by now ;)